04-10-2025 12:15 AM
Hey there fellows!
I'm having a bit of trouble understanding the best practice of segmentation in ACI.
I'll explain the use case.
We currently have an EPG called "cluster", that has a BD /20 associated with it,
There are contracts applied to it and everything works great.
We received the need to "segment" the existed EPG into 2 parts.
/21 for LoadBalancer and /21 for Nodes.
I would like to create 2 uSegs. apply the same contracts as in the "cluster" EPG,
create uSeg Attribute to match the IP of 192.200.0.0/21 and 192.200.0.8/21 accordingly to uSeg A and uSeg B.
And attach the same Physical Domain as to the "cluster" EPG.
After it is done, I try to remove the existing Contracts from the "cluster" EPG, but I lose communication and it doesn't appear to work.
Am I misunderstanding the usecase? is it possible.
The uSegs and the "cluster" EPG are part of the same BD and Physical Domain.
04-19-2025 06:56 AM
Any ideas ?
04-19-2025 02:33 PM
Hi @Rem Markov ,
I saw this previously, saw "µseg EPGS" and cringed. And forgot about it.
Since you've had no replies, I suspect many others have had the same reaction.
If I had to do this, I'd split the EPG into two EPGs - one for load balancer and one for nodes. However, I'm not really sure why the load balancers are being split off.
Perhaps my comment my spur someone who is a fan of µSeg EPGs to tell me I'm wrong and give you better advice.
04-20-2025 10:00 AM
I truly understand that people here really dislike useg, and I too find it a weird concept.
Now I would love to avoid it, but the question is how can I segment on BD to 2 epg when the segmentation should be by IP address?
Is there a better way?
04-20-2025 02:13 PM
Hi @Rem Markov ,
Now I would love to avoid it, but the question is how can I segment on BD to 2 epg when the segmentation should be by IP address?
04-21-2025 12:45 PM
I suppose it is a way of doing it, but i'm a bit confused.
Lets say now I have a vlan for "nodes" where is the vlan for load balancers?
Also, the case is like that,
I have 10 leafs and all the leaves have some servers attached to them.
I want to have one vlan running on each of the attached interfaces, the only segmentation I want is purely ip based.
Lets say on node A which is connected to leaf 103 eth1/4 might have some loadbalancers on his and also the node ips.
04-21-2025 02:19 PM - edited 04-21-2025 02:22 PM
Hi @Rem Markov ,
Sounds like you haven't completed step 1 from my last answer:
- Firstly, forget whatever you learned about "VLAN=subnet"
so - to your question
Lets say on node A which is connected to leaf 103 eth1/4 might have some loadbalancers on his and also the node ips.
Then you:
Alternatively, you can configure the AAEP so that VLAN y always gets traffic assigned to the Nodes_EPG - which is far easier but makes troubleshooting a little tricker later on. I'd suggest you use the same method that has been used previously.
Check some of my previous answers for more information about "mapping up" and "mapping down" if you are not familiar with the two ways of assigning VLANs to EPGs
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide